Skip to main content

New Method of Attack Abuses PowerPoint Slide Show

A new threat has been discovered within the CVE-2017-0199 vulnerability.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A new threat has been discovered within the CVE-2017-0199 vulnerability.

Affected platforms

The following platforms are known to be affected:

Threat details

CVE-2017-0199 was originally a zero-day Remote Code Execution vulnerability using a flaw within Microsoft Office to allow the execution of malware embedded within an infected Rich Text Format (RTF) file. The original flaw existed within the Windows Object Linking and Embedding (OLE) interface of Microsoft Office.

A new method of exploit has been discovered using a PowerPoint slideshow. The exploit arrives as an email attachment on an email claiming to be an Internet Service Provider as part of a spear-phishing campaign. When opened it shows the text “CVE-2017-8570” which is a different Microsoft Office vulnerability. CVE-2017-0199 is then exploited using a moniker script downloading a second-stage binary from a remote command and control server. This binary file finally downloads a Remote Access Trojan (RAT) and executes it.

Most ways of detecting CVE-2017-0199 focus on the RTF method of attack so the new vector, PPSX files, allows attackers to evade antivirus detection.


Remediation advice

Mitigation:

Remediation steps

Type Step
  • Ensure staff awareness of phishing attacks. Awareness campaigns should be provided and regularly refreshed to keep employees appraised of the latest phishing techniques.
  • Regular patching of systems with the latest security updates. Microsoft has already addressed this vulnerability back in April, users with updated patches are safe from these attacks.


Last edited: 17 February 2020 11:36 am